Network Access Control Policy
Identity-aware, posture-aware access to all corporate networks.
DOCUMENT
CS-03
OWNER
Director of Network Security
EFFECTIVE
January 1, 2026
REVIEWED
April 1, 2026
Purpose
Alexa Cybersecurity operates a Zero-Trust network model. There is no implicit trust based on network location. Every connection — internal, remote, partner, or guest — is subject to identity verification, device posture validation, and continuous authorization.
This Policy implements NIST SP 800-207 (Zero Trust Architecture) and ISO/IEC 27001 A.8.20 (Network security).
Network zones
- 01Production — customer-facing services and the systems that operate them. Access by approved engineers only, on managed devices, with MFA and just-in-time elevation.
- 02Corporate — staff productivity and internal SaaS. Access requires a managed identity and device posture check.
- 03Partner — segmented, tunnel-only access for vendors and integrators with contractual scope.
- 04Guest — internet-only, with no path to internal resources; PSK rotated per visit.
- 05Lab — research, malware analysis, and red-team work. Strictly air-gapped or token-mediated.
Access requirements
- 01Multi-factor authentication on every authentication event — phishing-resistant factors required for production.
- 02Device posture — full disk encryption, EDR running and reporting, OS within N-2 patch level, screen lock under 5 minutes.
- 03Identity Provider single source of truth — no local accounts on production endpoints.
- 04Least-privilege role assignments reviewed quarterly.
- 05Privileged access via Just-in-Time elevation with session recording.
Continuous monitoring
All network access is logged and forwarded to the SIEM with 90-day hot retention and 13-month cold retention. Anomaly detection flags impossible-travel events, off-hours privileged access, and lateral-movement patterns for SOC review.
Onboarding and offboarding
Access provisioning is triggered by an authoritative HR/contracts event and gated by completion of CS-01 Security Training. Offboarding revokes all credentials within 4 business hours of separation; for involuntary terminations, revocation is within 60 minutes.
/CONTROLLED_DOCUMENT
This document is the official, controlled version of CS-03 — Network Access Control Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.
VERSION
2026.1
REVIEWED
April 1, 2026
NEXT REVIEW
Annual


